Legal
Data Processing Agreement
The Article 28 GDPR terms on which DealLaunch AI processes personal data on your behalf. This is the agreement we offer as standard - you can read it in full before you upload anything, and we will countersign a copy on request.
Version 1.0 · Effective 27 July 2026
1. Roles and scope
This Data Processing Agreement (the Agreement) applies where DealLaunch AI processes personal data on behalf of a customer in the course of providing the DealLaunch AI service. It forms part of, and is subject to, the DealLaunch AI Terms.
The customer is the controller of the personal data it puts into its workspace - including its contacts, counterparties, notes and correspondence. DealLaunch AI is the processor of that data. Where the customer is itself a processor for its own client, DealLaunch AI acts as a sub-processor on the same terms.
DealLaunch AI is a separate controller only for its own account and billing data, which is governed by the Privacy notice rather than this Agreement.
2. Processing instructions
DealLaunch AI will process personal data only on the customer's documented instructions, which are given by the customer's use of the service and by this Agreement, unless required otherwise by applicable law - in which case DealLaunch AI will inform the customer before processing, unless that law prohibits it.
The subject matter is the provision of deal-workflow software. The duration is the term of the customer's subscription. The nature and purpose are the storage, organisation, transmission and retrieval of the customer's deal records and correspondence. The categories of data subject are the customer's business contacts, counterparties and its own personnel. The types of personal data are business contact details, professional role and firm, correspondence content, meeting notes and activity records. No special categories of personal data are required by the service, and the customer should not upload them.
DealLaunch AI will not sell personal data, will not use it for its own purposes, and will not use it to train artificial-intelligence models.
3. Confidentiality
DealLaunch AI ensures that any person authorised to process personal data is bound by an obligation of confidentiality, and limits access to those who need it to provide, secure or support the service.
4. Security
DealLaunch AI implements technical and organisational measures appropriate to the risk, including: encryption of data in transit and at rest; encryption of mailbox credentials at rest with AES-256-GCM, held server-side and never returned to a browser; per-workspace isolation enforced at the database layer by row-level security; private document storage reachable only through short-lived signed links; multi-factor authentication available on accounts; and an append-only record of material changes to a workspace.
The current state of these measures, including what is not yet in place, is published and kept current at deallaunch.ai/trust. The customer is responsible for the security of its own credentials, its own mailbox and the access it grants to its team.
5. Sub-processors
The customer gives general authorisation for the sub-processors published at deallaunch.ai/sub-processors, which as at the date of this Agreement are Supabase, Vercel, Anthropic, OpenAI, Stripe.
DealLaunch AI will give at least 30 days' notice by email before a new sub-processor with access to workspace data begins processing, and will update the published list on the same day. If the customer reasonably objects on data-protection grounds within that period, it may terminate the affected part of the service without penalty and export its data.
DealLaunch AI imposes data-protection obligations on each sub-processor no less protective than those in this Agreement, and remains fully liable to the customer for their performance.
Outreach is sent directly from the customer's own mailbox, through Microsoft Graph or the customer's own SMTP server. There is no mail sub-processor and message content is not relayed through DealLaunch AI infrastructure for delivery.
6. International transfers
Application server functions run in Frankfurt, Germany (fra1). The database and file storage are located in the region stated at deallaunch.ai/trust.
Where a sub-processor processes personal data outside the European Economic Area or the United Kingdom - which today applies to the artificial-intelligence and payment providers listed on the sub-processor page - the transfer is made under the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and subject to the supplementary measures described on the trust page.
7. Assistance to the controller
Taking into account the nature of the processing, DealLaunch AI will assist the customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the customer's obligation to respond to requests from data subjects exercising their rights. The customer can satisfy most such requests itself, directly in the product, because it can search, correct, export and delete the records in its own workspace at any time.
DealLaunch AI will also provide the customer with reasonable assistance in relation to data-protection impact assessments and prior consultation with a supervisory authority, taking into account the information available to it.
8. Personal data breaches
DealLaunch AI will notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the customer's data. The notification will describe the nature of the breach, the categories and approximate volume of data and data subjects affected so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not available at once, information will be provided in phases as it becomes available.
9. Return and deletion
The customer may export its workspace at any time during the term, without notice to DealLaunch AI and without charge, from Settings then Security. The export includes deals, contacts, documents and their download links, drafts, templates, mandate terms and the activity record.
On termination, DealLaunch AI will, at the customer's choice, return or delete the personal data it processes, and delete existing copies within 30 days, unless retention is required by applicable law. Routine encrypted backups are deleted on their normal rotation, within 90 days of termination.
10. Audit
DealLaunch AI will make available to the customer the information necessary to demonstrate compliance with Article 28 GDPR, including the published trust and sub-processor pages and reasonable answers to written security questionnaires.
Where that information is not sufficient for the customer's own regulatory obligations, DealLaunch AI will contribute to an audit conducted by the customer or an independent auditor mandated by it, on reasonable prior written notice, no more than once in any twelve-month period except following a personal data breach, during business hours, and subject to confidentiality.
11. Term, precedence and law
This Agreement takes effect when the customer begins using the service or signs it, whichever is earlier, and continues for as long as DealLaunch AI processes personal data on the customer's behalf.
In the event of a conflict between this Agreement and the DealLaunch AI Terms in relation to the processing of personal data, this Agreement prevails.
This Agreement is governed by the law stated in the DealLaunch AI Terms, without prejudice to the mandatory rights of data subjects under applicable data-protection law.
Signing a copy
Email hello@deallaunch.ai with your firm's legal name and registered address and we will return a countersigned copy of this agreement, normally the same working day. If your firm needs its own DPA form used instead, send it and we will review it.